Critical Alert 2 Active Exploits Detected Today

CVE-2026-102490 — Zammad GmbH Zammad Improper Privilege Management Vulnerability →
CVE-2026-102489 — Zammad GmbH Zammad Session Fixation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2025-32433NVD

Vulnerability Summary

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
Severity Level
CRITICAL(10.0)
Published Date
Apr 16, 2025
Last Modified
Jul 30, 2025
PoC
Available(Metasploit)
Exploitation Status
ACTIVE
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics — Score 10.0 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Erlang Erlang\/otp < 25.3.2.20
  • Erlang Erlang\/otp >= 26.0 and < 26.2.5.11
  • Erlang Erlang\/otp >= 27.0 and < 27.3.3
  • Cisco Confd Basic < 7.7.19.1
  • Cisco Confd Basic >= 8.0.18 and < 8.1.16.2
  • Cisco Confd Basic >= 8.2 and < 8.2.11.1
  • Cisco Confd Basic >= 8.3 and < 8.3.8.1
  • Cisco Confd Basic >= 8.4 and < 8.4.4.1
  • Cisco Network Services Orchestrator < 5.7.19.1
  • Cisco Network Services Orchestrator >= 5.8 and < 6.1.16.2
  • Cisco Network Services Orchestrator >= 6.2 and < 6.2.11.1
  • Cisco Network Services Orchestrator >= 6.3 and < 6.3.8.1
  • Cisco Network Services Orchestrator >= 6.4 and < 6.4.1.1
  • Cisco Network Services Orchestrator >= 6.4.2 and < 6.4.4.1
  • Cisco Cloud Native Broadband Network Gateway < 2025.03.1
  • Cisco Inode Manager
  • Cisco Smart Phy < 25.2
  • Cisco Ultra Packet Core < 2025.03
  • Cisco Ultra Services Platform
  • Cisco Staros < 2025.03
  • Cisco Optical Site Manager < 25.2.1
  • Cisco Ncs 2000 Shelf Virtualization Orchestrator Firmware < 25.1.1
  • Cisco Enterprise Nfv Infrastructure Software < 4.18
  • Cisco Ultra Cloud Core < 2025.03.1
  • Cisco Rv160w Firmware
  • Cisco Rv260 Firmware
  • Cisco Rv160 Firmware
  • Cisco Rv260p Firmware
  • Cisco Rv260w Firmware
  • Cisco Rv340 Firmware
  • Cisco Rv340w Firmware
  • Cisco Rv345 Firmware
  • Cisco Rv345p Firmware
Patched Versions
  • Erlang Erlang\/otp 25.3.2.20
  • Erlang Erlang\/otp 26.2.5.11
  • Erlang Erlang\/otp 27.3.3
  • Cisco Confd Basic 7.7.19.1
  • Cisco Confd Basic 8.1.16.2
  • Cisco Confd Basic 8.2.11.1
  • Cisco Confd Basic 8.3.8.1
  • Cisco Confd Basic 8.4.4.1
  • Cisco Network Services Orchestrator 5.7.19.1
  • Cisco Network Services Orchestrator 6.1.16.2
  • Cisco Network Services Orchestrator 6.2.11.1
  • Cisco Network Services Orchestrator 6.3.8.1
  • Cisco Network Services Orchestrator 6.4.1.1
  • Cisco Network Services Orchestrator 6.4.4.1
  • Cisco Cloud Native Broadband Network Gateway 2025.03.1
  • Cisco Smart Phy 25.2
  • Cisco Ultra Packet Core 2025.03
  • Cisco Staros 2025.03
  • Cisco Optical Site Manager 25.2.1
  • Cisco Ncs 2000 Shelf Virtualization Orchestrator Firmware 25.1.1
  • Cisco Enterprise Nfv Infrastructure Software 4.18
  • Cisco Ultra Cloud Core 2025.03.1
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.